Skip to content

As we wrap up the last few months of 2024, DORA looms ever larger on the horizon. The Digital Operational Resilience Act, required of financial entities in the European Union, goes into effect January 17, 2025. Banks, insurance companies, and Information and Communications Technology (ICT) third-party service providers are among the institutions that must comply with the regulations, which are designed to enable cyber resiliency.

It’s crucial for all stakeholders to understand the key provisions and the impact they will have on the financial ecosystem. Here’s a deeper dive into the main components of DORA and what they mean for the industry.

1. Risk Management Requirements

DORA introduces stringent requirements for financial entities to establish and maintain robust digital operational resilience frameworks. This means that firms must have comprehensive policies in place to manage ICT risks. These policies should cover the entire lifecycle of ICT systems, from development and deployment to maintenance and decommissioning. Financial entities are expected to regularly review and update their risk management strategies to adapt to new and emerging threats.

2. Incident Reporting

One of the pivotal elements of DORA is the obligation for financial entities to promptly report significant cyber incidents to their respective regulatory authorities. This provision ensures that there is a timely flow of information between financial institutions and financial supervisors, which is crucial for managing systemic risks and enhancing the overall resilience of the financial sector. The act specifies the types of incidents that must be reported, the reporting timelines, and the detailed information that must be included in the reports.

3. Digital Operational Resilience Testing

To ensure that financial entities can effectively withstand and recover from ICT disruptions, DORA mandates regular testing of digital resilience. This includes a range of testing activities, such as vulnerability assessments, penetration testing, and scenario-based exercises. These tests are designed not only to identify vulnerabilities in ICT systems and processes, but primarily to assess the effectiveness of the entity’s preventive, detection, response, and recovery capabilities.

4. Third-Party Risk Management

Recognizing the increasing reliance on third-party ICT service providers, DORA sets out specific requirements for managing risks associated with these external parties. Financial entities must carefully select and monitor their service providers to ensure they comply with high resilience standards. They must conduct thorough due diligence before entering into agreements and continuously monitor the service providers’ performance and compliance with contractual obligations.

5. Oversight Framework

DORA establishes an oversight framework that allows European supervisory authorities to directly oversee critical ICT third-party service providers. This framework is intended to compel providers to adhere to stringent resilience standards, given their importance to the financial sector. The oversight includes regular assessments and, if necessary, the imposition of remedial actions to address identified deficiencies.

Penalties for Noncompliance

Noncompliance with DORA can result in significant penalties, which are crucial in maintaining the integrity and effectiveness of the act. These can vary depending on the severity and nature of the offense. They are designed to be dissuasive and proportionate to the financial strength and size of the entity, as well as the extent of the disruption caused by the noncompliance.

For minor infringements, financial entities might face warnings or reprimands. However, for more serious breaches, the penalties can include hefty fines. In cases of repeated noncompliance or particularly egregious breaches, regulatory authorities have the power to impose additional sanctions. These can include the revocation of licenses, temporary bans on conducting certain business activities, or other restrictions necessary to protect the financial system.

Positive Impact on Financial Stability

The introduction of DORA marks a significant step forward in the quest for greater digital operational resilience in the financial sector. By setting out clear requirements for financial entities and service providers, the EU aims to safeguard the sector from ICT-related disruptions and threats. It is imperative for all affected entities to fully grasp these provisions and prepare accordingly to ensure compliance and enhance their resilience capabilities.

This comprehensive approach not only enhances the security of individual institutions but also bolsters the stability of the financial system as a whole. As we move closer to January 2025, the anticipation of DORA’s impact continues to build, promising a new era of digital resilience in finance.

Learn more about managing DORA compliance with Commvault® Cloud here.

Learn more about how you can prepare for the Digital Operational Resilience Act in our Exploring DORA blog series:

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Wednesday, September 11, is Patriot Day and a National Day of Service and Remembrance in the United States as we commemorate the 23rd anniversary of September 11, 2001. 

September 11, 2001, was a loss felt worldwide. When I reflect on the anniversary of 9/11 each year, I’m reminded of how our communities were united in the aftermath of this tragedy. We put aside our divisions and united in caring for one another, supporting one another, and projecting hope.

Today and every day, we remember those who lost their lives, thank the brave first responders who put their lives on the line, and honor the sacrifices that have been made in the years since to protect our freedoms. 

As a U.S. Navy Veteran, I am proud to be the Executive Sponsor of our Veterans’ Employee Resource Group (VALOR ERG) at Commvault. Each year we honor the anniversary of 9/11 with our annual Commvault Climbs Challenge – an initiative that challenges our Vaulters to climb as many as 104 flights of stairs to honor the brave firefighters and first responders who climbed the stairs of the Twin Towers of the World Trade Center to save the lives of others. When I see the photos and videos of Vaulters honoring these heroes, I’m incredibly moved by the support across our company as we care for each other and honor our communities.   

The anniversary of 9/11 is a day to hold your loved ones close, reflect on the bravery of the first responders, honor the lives lost and forever changed that day, and thank those who have volunteered to serve their country in response to tragedy. I encourage you to take time today to do just that.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The persistent and evolving nature of cyber threats demands innovation. At Commvault, we are committed to a cadence of innovation to develop and deliver products to the market that aligns with the latest needs of customers.

With this commitment in mind, we are thrilled to share that Commvault Cloud was ranked 1st in five of the six use cases in the 2024 Gartner® Critical Capabilities for Enterprise Backup and Recovery Software Solutions. The report evaluated vendor products based on six use cases against 15 critical capabilities. We feel this report – paired with the 2024 Gartner® Magic Quadrant for Enterprise Backup and Recovery Software Solutions – is a valuable source of information to stay on top of that latest backup and recovery requirements customers expect from vendors.

Businesses today are increasingly focusing on cyber resilience to protect their operations and data against cyber threats. This shift is driven by the need to support secure innovation and maintain customer trust.

By adopting advanced security solutions with comprehensive protection and recovery capabilities, organizations are better prepared to handle cyber threats and thrive in a competitive market by minimizing downtime and maintaining seamless service delivery.

As per us, Commvault has excelled in this area, and hence was positioned as a Leader in the Gartner Magic Quadrant for the 13th consecutive time and was once again recognized in the Gartner Critical Capabilities report.

Continuously evolving to meet customer needs, Commvault has helped numerous businesses strengthen their security postures. This recognition, we feel, reaffirms our dedication to delivering top-tier cyber resilience solutions, enabling businesses to protect their assets and confidently navigate the digital landscape.

We look forward to continuing to innovate and deliver cyber resilience solutions based on the needs of our customers to ensure their businesses maintain a state of continuity.


Gartner, Critical Capabilities for Enterprise Backup and Recovery Software Solutions, 4 September 2024, By Jason Donham, Michael Hoeck, Rene Rodriguez, Chandra Mukhyala.

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, Magic Quadrant is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved.

Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s Research & Advisory organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Updated: January 27, 2026

Organizations of all sizes are rethinking data protection as ransomware, cloud growth, and hybrid learning to reshape how information is stored and accessed. Commvault® Cloud and Commvault Cloud Backup & Recovery help IT teams, students, and educators build cyber resilience with capabilities to unify backup, recovery, and security controls.

This guide highlights the real-world challenges of modern data protection and practical strategies to address them, based on a Resilience Rundown conversation with DataPivot Technologies.

What Is Data Protection in Modern IT?

Data protection brings together technology, processes, and people to keep data available, protected, and recoverable. It includes backup and recovery, long-term retention, ransomware resilience, and regulatory compliance.

Today’s environments require protection across:

  • On-premises data centers
  • Public and private clouds
  • SaaS applications
  • Endpoint devices and remote users

A single unprotected dataset can quickly become a weak point during an outage or attack.

The DataPivot Perspective

DataPivot Technologies is a Commvault solution provider focused on enterprise technology: data protection, data security, data storage, SaaS, and cloud infrastructure. The company supports more than 150 customers and has been recognized as a top Commvault provider in the Eastern United States.

Founder and CEO Giles Westie emphasizes that DataPivot is “a customer service company that provides technology solutions.” This approach combines technical expertise with consultative guidance to help customers navigate today’s complex IT landscape.

How Data Protection Has Evolved

Two decades ago, data protection often meant nightly tape backups and occasional disaster recovery tests. Today, four major shifts make protection more complex—and more essential.

  1. Cloud and SaaS growth
    Data now spans multiple clouds and SaaS applications, each with unique requirements and potential protection gaps. Legacy tools were not designed for this level of sprawl.
  2. Always-on services 
    Students, clinicians, and employees expect systems to be available at all times. Even brief disruptions can interrupt classes, delay operations, or affect revenue.
  3. Ransomware and advanced threats 
    Attackers increasingly target backup systems alongside production environments. Quickly restoring clean data is now as important as preventing attacks.
  4. Regulatory and privacy requirements 
    Compliance frameworks require organizations to show they can protect and recover sensitive information and maintain auditable data protection practices. Learn more about Commvault Cloud compliance.

Key Challenges in Modern Data Protection

Challenge 1: Multiple point solutions

Many organizations use separate tools for backup, SaaS protection, archives, and disaster recovery—each with its own console, policies, and reporting. This can lead to:

  • Inconsistent protection levels
  • Gaps for newer or cloud-native workloads
  • Complex incident response

DataPivot and Commvault recommend moving toward a unified platform that provides a single view of backup, recovery, and security posture.

Challenge 2: Ransomware and cyber resilience

Modern ransomware campaigns can:

  • Spread laterally across data centers and clouds
  • Target or attempt to delete backups
  • Disrupt identity and authentication systems

Cyber resilience focuses on continuing operations and restoring critical services after an attack. Core elements include:

  • Immutable backups and air-gapped copies
  • Early threat and anomaly detection
  • Practiced recovery playbooks

Commvault Cloud brings these capabilities together so security and backup teams can work from shared insights.

Challenge 3: Complexity of hybrid environments

Most organizations operate across on-premises infrastructure and multiple clouds. Students and staff may use SaaS applications, personal devices, and campus systems throughout the day.

Common challenges include:

  • Inconsistent protection policies
  • Limited visibility into SaaS backup status
  • Difficulty meeting recovery time objectives (RTOs)

A unified platform helps teams apply policies consistently across all locations.

Challenge 4: Skills and staffing

IT teams often have to manage data protection alongside many other responsibilities. As environments grow, so does operational overhead.

Educational and training resources, such as Commvault’s Readiverse Academy and partner-led workshops, help teams build skills in:

  • Backup and recovery design
  • Cloud and SaaS data protection
  • Ransomware readiness and response

The Role of Commvault and DataPivot

DataPivot collaborates with Commvault to deliver a single platform for data protection and cyber resilience. Together they help customers:

  • Consolidate legacy backup tools into Commvault Cloud
  • Design architectures that protect data across data centers, clouds, and SaaS
  • Implement ransomware-ready solutions with immutable storage
  • Run test recoveries and exercises for disaster and cyber events

Commvault Cloud Backup & Recovery delivers policy-driven protection, flexible recovery options, and broad workload coverage. Commvault Cloud’s cyber resilience features help identify risky data, automate recovery workflows, and can help reduce downtime.

Planning for Cyber Resilience

Cyber resilience goes beyond backups. It answers the question: “How quickly can we return to safe operations after a major incident?”

Core elements include:

Prevention

  • Hardening backup infrastructure
  • Role-based access control and multifactor authentication
  • Integration with security operations tools

Preparedness

  • Clear runbooks for cyber incidents
  • Pre-defined recovery tiers for critical applications
  • Regular recovery testing using non-production environments

Recovery

  • Fast identification of clean restore points
  • Orchestrated recovery of applications, not just VMs
  • Communication with stakeholders, students, and customers

DataPivot often walks customers through scenarios that range from simple file restores to disaster or ransomware recovery. This exercise helps align expectations, budget, and technology.

Success Metrics for Data Protection

To know whether a data protection strategy is working, organizations can track metrics such as:

  • Downtime reduction: Hours of avoided or reduced outages
  • Recovery time: Ability to meet RTOs for critical services
  • Backup reliability: Percentage of successful backup jobs
  • Ransomware recovery readiness: Number of tested recovery scenarios per year

These metrics help leadership understand the value of investing in resilience.

Key Takeaways for Students and Early-Career IT Professionals

  • Think in terms of systems, not just backups. Data protection includes security, identity, storage, and networking.
  • Understand that cloud does not automatically equal protection. SaaS data often needs separate protection.
  • Recognize that ransomware is a question of “when,” not “if,” and that recovery is a core security discipline.
  • Learn how platforms like Commvault Cloud integrate with security tools, cloud providers, and partners to provide end-to-end resilience.

Explore Commvault Cloud and Commvault Cloud Backup & Recovery to see how a unified platform simplifies backup and recovery across hybrid and multi-cloud environments.

Quick Summary 

  • Data protection now spans on-premises, cloud, and SaaS.
  • Ransomware and advanced threats make recovery as important as prevention.
  • Multiple point tools increase complexity and risk.
  • Commvault Cloud and partners like DataPivot provide a unified platform for backup, recovery, and cyber resilience.
  • Success is measured by reduced downtime, faster recovery, and tested ransomware readiness.

FAQ

Q: What is data protection in modern IT?
A: Data protection is the practice of keeping data available, protected, and recoverable across on-premises, cloud, and SaaS environments.

Q: How is cyber resilience different from traditional backups?
A: Cyber resilience focuses on keeping the business running during and after cyberattacks by combining security, backup, and orchestrated recovery.

Q: Why are multiple point backup tools a problem?
A: Multiple tools create coverage gaps, inconsistent policies, and slow incident response because teams must manage many consoles and reports.

Q: How does Commvault Cloud help with ransomware recovery?
A: Commvault Cloud offers immutable backups, threat detection, and automated recovery workflows to restore clean data quickly after an attack.

Q: What role does DataPivot play in data protection projects?
A: DataPivot designs and implements data protection solutions using Commvault technology, helping customers navigate complexity with expert guidance.

Q: Which metrics show that a data protection strategy is working?
A: Key metrics include the potential for minimized downtime, faster recovery times, high backup success rates, and tested ransomware recovery scenarios.

You can learn more about DataPivot on its website or by email sales@datapivottech.com.

Watch the full episode here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Resilience means coming back again and again and again – I’m proud to say we’ve done just that!  

Commvault was named a Leader – for the 13th consecutive time – in the 2024 Gartner® Magic Quadrant™ for Enterprise Backup and Recovery Software Solutions.

In the same week, we were also named a Leader and took the top position in the GigaOm Sonar for Cloud-Native Data Protection2. This is a moment to celebrate and a moment to realize just how critical modern cyber resilience is today for businesses around the world.

Cyber resilience is the key to business continuity, and we believe recognition like this validates that Commvault’s products and end-to-end strategy are truly differentiated in the market. Customers need to know when the chips are down, they can recover and be resilient, and that’s what we uniquely enable them to do.

The Gartner Magic Quadrant is a culmination of research in a specific market, giving you a wide-angle view of the relative positions of the market’s competitors. We feel our ability to empower customers globally has – again, and again, and again – fueled our strong quarterly results, as we just reported our third quarter of double-digit consecutive revenue growth.

The World Moving Forward Is Very Cloudy

Innovation and the unwavering commitment to solve our customers’ biggest challenges continues to drive us every day and into the future. Gartner is predicting that “By 2027, more than 50% of enterprise-managed data will be created and processed outside the data center or cloud, which is a major increase from 20% in 20231,”and we feel we have developed the cloud-native software to do it right.

To that end, I’m thrilled that GigaOm also published its Sonar for Cloud-Native Data Protection, naming Commvault as the top Leader. This Sonar thoroughly evaluated 13 vendors across 10 key characteristics for cloud-native data protection – and we knocked it out of the park. Commvault Cloud enables data security and recovery in the cloud.Our customers can back up, monitor, report, manage and recover their data, wherever it lives, from one central cloud-based platform. It’s an innovative approach to delivering cyber resilience for the hybrid and cloud-first enterprise.

There’s a lot more to come that we feel will keep us at the forefront of innovation as we continue to deliver resilience that addresses our customers’ key careabouts in an ever-evolving threat landscape. Join us for the ride and stay tuned. 

Want to experience the ultimate weapon against ransomware? Register now to experience Commvault Cloud free for 30 days.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Our U.S. internship program concluded last week, and I’m so incredibly proud of the work done by our intern class this summer. At Commvault, we believe that investing in the next generation of leaders helps shape a better future for us all.

Commvault’s internship program provides students with real, meaningful work experience that empowers them as young professionals to learn and grow. Our interns get hands-on experience working on company-wide projects that matter to them and to Commvault. We prioritize training, collaboration, mentorship programs, and networking opportunities to enable our interns to expand their skillsets and professional network. These values are all core to this program.

Each year, our internship program concludes with a project contest – an exciting opportunity for our interns to present an idea, initiative, or improvement tied to their department and field of study to a panel of cross-functional leaders. I must say, the innovation we see each year is quite extraordinary.

This year, we saw projects spanning across our product portfolio, employer brand initiatives, and industry analyst accolades. It’s not only important for us to give our interns an exceptional experience during their time at Commvault, but we also want them to learn exceptional lessons as they prepare to go back to their universities or take the first step into their professional careers.

When I reflect on our internship program, I’m reminded why it’s so important to have managers, leaders, and mentors to provide advice and insight that these young professionals will carry with them throughout their careers. I’m so proud of our culture of continuous learning and caring here at Commvault and how it allows us to embrace and celebrate the ideas of our global Vaulter community.

I want to extend a huge thank you to our 2024 U.S. summer intern class for all their amazing contributions to Commvault. These are the minds that will help shape the future for us all.

Learn more about how you can grow your career at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Commvault is excited to share that Commvault Platform Release 2024E is now generally available. Customers can visit documentation.commvault.com, and download the Commvault Cloud platform release.

As we’ve journeyed with our customers over the past year, we’ve noticed several critical digital trends that have informed this platform release. First, cyber threats are getting more complex, affecting our ability to respond, recover, and stay resilient, especially with the rise of ransomware. Second, data is getting more spread across different clouds, regions, and apps, making it challenging to maintain a robust and reliable resilience approach.

There are several new capabilities that can help bolster security across hybrid environments and deliver rapid, reliable data recovery from any location. The highlights include:

Security – Building for Cyber Resiliency

Through our commitment to innovation and collaboration with our customers and partners, Commvault aims to build a safer digital landscape by providing solutions to help anticipate, withstand, recover, and adapt to cyber threats.

Our alignment with industry standards such as NIST Cyber resiliency (800-160) and the NIST 2.0 Cyber Security frameworks demonstrate the maturity in our approach, helping our customers navigate the complex cyber security landscape.

Threat Scan Support for VMs

Cyber threats impact backup content, making recovering good backup versions difficult. Data is encrypted and backed up with ransomware, and data recoveries can reinfect an organization. Manually validating backup content is tedious and time-consuming, and involves trial and error.

Now, you can conduct thorough scans of your VM backups to detect any potential malware infections. Doing so will equip you to take prompt and well-informed recovery measures. Swiftly identify and isolate any threats within the backups to facilitate the rapid recovery of uncontaminated data, effectively preventing reinfection.

Post-Quantum Security Enhancements

Quantum computing harnesses the extraordinary principles of quantum mechanics to manipulate quantum bits (qubits), which simultaneously possess the unique capability of existing in multiple states. This allows for solving specific computational problems at an exponential speed compared to classical computers, potentially leading to groundbreaking advancements in research and science.

On the downside, Quantum computers threaten to shatter current encryption standards that safeguard data. This can lead to exposed financial records, personal information, intellectual property, and more. Businesses are forced to adapt their cybersecurity strategies for a future where current encryption methods may be compromised by adopting Post-Quantum Cryptography (PQC). For a deeper understanding of this revolutionary technology, we invite you to explore our blog post on the topic. 

Commvault has implemented a pluggable post-quantum cryptography framework to support current algorithms outlined in NIST FIPS 203, 204, and 205 publications as well as the ability to easily integrate new algorithms as PQC evolves in the future.

 Splunk for SOAR Integration

Security teams must respond quickly to security events to minimize the impact of cyber threats. The good news is that Security Orchestration Platforms like Splunk can help correlate and orchestrate responses across the organization.

Our integration with Splunk SOAR enables security teams to monitor threat indicators, Commvault alerts, and audit events within Splunk, allowing them to respond with orchestrated actions and playbooks to enhance their security posture. This centralizes security data for better collaboration with SecOps and faster identification and response to security incidents.

Recovery

Our latest recovery features continue to extend our coverage of cloud-native workloads to seamlessly protect and recover data in one cyber resilient platform. 

Domain Controller Recovery with Cleanroom

Cyber threats often target Active Directory because it governs access to applications in most enterprise organizations.   

The cleanroom recovery of Active Directory Domain Controller enables secure and rapid recovery of the infrastructure needed to authenticate users and provide access control functions. This means recovered applications are accessible for conducting cyber recovery plan testing as well as application validation. 

Learn More About Commvault Cloud Platform Release 2024E

Take your cyber resilience strategy to the next level and fully leverage the capabilities of Commvault Cloud. Get started with Commvault Cloud Platform Release 2024E:

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

In the fast-paced world of software development, the pressure to deliver new features and patches quickly is immense. However, the recent CrowdStrike incident serves as a stark reminder that even the most well-intentioned updates can have unintended consequences when released without proper precaution. 

The Problem: CrowdStrike’s Patch Gone Wrong

In July 2024, CrowdStrike, a leading cybersecurity firm, released a security patch designed to protect its customers from a critical vulnerability. Unfortunately, shortly after deployment, the patch itself triggered widespread outages, impacting a significant portion of CrowdStrike’s customer base. 

This incident highlighted a fundamental challenge in software deployment: the difficulty of fully anticipating how a change will interact with the complex, real-world environments in which software operates.

The Solution: Staggered Releases – A Safety Net for Software Deployments

The CrowdStrike incident underscores the importance of staggered releases as a risk mitigation strategy. Instead of deploying a change to the entire user base at once, a staggered release gradually rolls out the update to a smaller subset of users over time. This approach offers several key benefits:

  1. Early issue detection: By exposing the change to a limited group, potential problems can be identified and addressed before they impact a larger audience. This minimizes the blast radius of any unforeseen issues.
  2. Faster rollback: In the event of a serious issue, a staggered release allows for a quicker rollback to the previous version, limiting the overall impact on users.
  3. Controlled testing in production: Staggered releases create a controlled environment for testing changes in real-world scenarios, complementing pre-production testing efforts.
  4. Customer confidence: Companies that adopt staggered releases demonstrate a commitment to quality and risk management, which can enhance customer trust.

Commvault’s Proven Approach

Here at Commvault, we have long recognized the value of staggered releases. We employ a multi-layered approach that includes rigorous testing in pre-production environments, followed by phased rollouts to our SaaS and software customers. This meticulous process allows us to thoroughly validate changes in real production environments before they reach a wider audience, helping to enable the stability and reliability of our solutions.

Staggered Releases: More Than Just a Best Practice

While the CrowdStrike incident may seem like an isolated event, it’s a harsh reminder that no software release is foolproof. Staggered releases provide a crucial safety net that can prevent minor issues from escalating into major disruptions. By adopting this approach, companies can not only protect their customers but also safeguard their own reputation and business continuity.

Key Takeaways for Software Development Teams

  • Prioritize risk mitigation: Always consider the potential impact of a change, no matter how small or beneficial it may seem.
  • Test, test, test: Thorough testing is essential, but it’s impossible to anticipate every scenario. Staggered releases offer an additional layer of validation.
  • Phased rollout: Gradually introduce changes to your user base, starting with a small subset and expanding over time.
  • Monitor closely: Track the performance of the change after each phase of the rollout and be prepared to adjust your plan if necessary.

By embracing staggered releases as a standard practice, software development teams can strike the right balance between innovation and stability, delivering value to customers while minimizing the risk of disruption.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

At Commvault, wellness continues to be a top priority for us. The why is simple – we know that at the end of the day, caring for ourselves allows us all to thrive and be our best selves. And as we continue to prioritize wellness, we’re taking a holistic approach to health, focusing on physical, mental, and financial wellbeing resources for our Vaulters. 

I often find that financial wellbeing gets less attention than physical and mental wellbeing, but at Commvault we believe it’s equally as important. However, the reality is, managing money effectively isn’t something that comes easily to us all. This is why we’re giving our Vaulters the tools they need to create a strong and resilient financial future with Origin, a financial wellness offering.

Origin has cutting-edge technology that allows our Vaulters to grow, track, manage, and save, all from one place. We’re thrilled to have this financial wellness offering now available to all our Vaulters across the world.

Caring for our wellbeing allows us to be our best (and most resilient!) selves, both at home and at work. We continue to evolve our global wellness offerings to best fit the needs of our Vaulters, so stay tuned.

Click here to learn more about what it’s like to work at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

The anchor to this article is a fireside chat with the Commvault Field Chief Technology Officer for APAC, Gareth Russell, and Olympian and World Champion swimmer Brooke Hanson.

Join us as we explore this unexpected connection, delving into the shared characteristics and strategies that enable both cyber resilience and athletic excellence. Discover how teamwork and technology play pivotal roles in both cybersecurity and sports, empowering individuals and teams to effectively combat threats and achieve peak performance. We would love for you to join the discussion, provide your own feedback, insights and comments as we unveil the unexpected yet profound intersection of cyber resiliency and professional sports.

In the world of cyber resiliency, just like in professional sports, preparation and consistency are paramount. Cyber professionals engage in regular training and simulations to sharpen their skills and stay prepared for potential attacks, much like athletes train and practice to improve their performance.

These training sessions involve simulating real-world scenarios, conducting vulnerability assessments, and practicing incident response plans. By continuously testing their defense and recovery procedures, cyber professionals enable their readiness to combat emerging threats and recover systems and data in the event of a cyberattack.

Both cyber professionals and athletes adhere to strict routines to maintain their proficiency and effectiveness. In cybersecurity, routines include anomaly detection, vulnerability assessments, and monitoring logs to identify any suspicious activities. Athletes, on the other hand, follow rigorous training schedules, including physical conditioning, skill development, and recovery. These routines help maintain peak performance, reduce the risk of injuries, and ensure consistent results in both fields.

Maintaining unwavering focus and concentration is vital for cyber professionals to detect and respond to threats effectively. They must constantly monitor systems, analyze data, and stay alert to any anomalies that could indicate a potential attack.

Similarly, athletes must stay focused during competitions, maintaining their composure and executing their strategies amid distractions and pressure. This ability to concentrate allows both cyber professionals and athletes to perform at their best and achieve their objectives.

The Critical Role of Teamwork and Support in Achieving Success

In the realm of cyber resiliency, teamwork is the cornerstone of an effective defense against cyber threats, including the ability to respond and recover from such threats. Just as a sports team relies on the coordinated efforts of its players to achieve victory, a successful cybersecurity strategy hinges on the seamless collaboration of experts from various disciplines. This collaborative approach enables organizations to leverage the diverse strengths and expertise of their cybersecurity professionals, supporting comprehensive protection against evolving threats.

Responding to a cyberattack will take support from your entire organization from cybersecurity and IT teams all the way to the executive team. There are many elements that need to be considered, including communications, public relations, incident response, eDiscovery and data recovery, and there are many non-technical elements that need to be executed.

 Having a holistic and comprehensive cyber resiliency plan allows you to be clear with the roles and responsibilities, including expectations and accountability. If they combine this plan with regular testing and simulation, organizations should be in the best position to respond and recover from a cyberattack. It becomes muscle memory without having to make decisions under stress – again, remarkably like how athletes prepare for big competitions.

Teamwork, support, open communication, and trust are indispensable elements for success in both cyber resiliency and professional sports. By fostering these essential qualities, organizations can build a robust defense against cyber threats and achieve their goals in the ever-evolving digital landscape.

The Impact of Technology

Technology stands as a transformative force in both cybersecurity and professional sports, revolutionizing preparation, performance, and recovery in both domains. Advanced data analytics, artificial intelligence, and machine learning have emerged as indispensable tools for cyber professionals and athletes alike.

In the realm of cybersecurity, these innovative technologies facilitate the identification of threats, enhance decision-making, and automate processes, enabling organizations to fortify their defenses against cyberattacks. Similarly, in professional sports, data analytics empower coaches and trainers to optimize training regimens, identify talent, and devise winning strategies.

Virtual and attack simulation technologies, such as Cyber Ranges and Red Teaming, further bolster preparedness and performance. In cybersecurity, simulations provide a safe environment for cyber professionals to test their response plans and hone their skills. These simulations provide a real-world attack simulation where defenders and organisations can test and stress their end-to-end cyber resiliency plans.

In sports, virtual reality technology enhances training by simulating real-world scenarios, allowing athletes to refine their techniques and strategies without the risk of injury. In swimming, we have seen the introduction of technology visually help athletes to identify improvements in their technique.

Just as professional athletes prepare and train rigorously, strategize meticulously, and adapt swiftly to the ever-changing dynamics of their sport, organizations must cultivate a robust cyber resilience strategy. This involves continuous testing, adopting advanced technologies, and fostering a culture of preparedness and agility. Both realms demand a proactive approach, unwavering commitment, and the ability to recover quickly from setbacks.

We’d love to hear your thoughts on this analogy. Do you see other parallels between cyber resilience and professional sports? How does your organization prepare for cyber threats, and what strategies have you found most effective? Share this post on LinkedIn and join the discussion.

It is 2024, and the 33rd Summer Olympics is wrapping up, with the city of lights Paris both entertaining and hosting over 10,000 athletes from 206 countries competing in 32 sports – an event which truly captures a global audience.

Today, we step back and look at the collision between cyber resiliency and professional sports and an intriguing parallel emerges between these two seemingly disparate worlds. From the rigorous training and strict routines to the unwavering discipline and focus required, cyber professionals and athletes exhibit striking parallels in their respective domains that are crucial for success.

The anchor to this article is a fireside chat with the Commvault Field Chief Technology Officer for APAC, Gareth Russell, and Olympian and World Champion swimmer Brooke Hanson.

Join us as we explore this unexpected connection, delving into the shared characteristics and strategies that enable both cyber resilience and athletic excellence. Discover how teamwork and technology play pivotal roles in both cybersecurity and sports, empowering individuals and teams to effectively combat threats and achieve peak performance. We would love for you to join the discussion, provide your own feedback, insights and comments as we unveil the unexpected yet profound intersection of cyber resiliency and professional sports.

In the world of cyber resiliency, just like in professional sports, preparation and consistency are paramount. Cyber professionals engage in regular training and simulations to sharpen their skills and stay prepared for potential attacks, much like athletes train and practice to improve their performance.

These training sessions involve simulating real-world scenarios, conducting vulnerability assessments, and practicing incident response plans. By continuously testing their defense and recovery procedures, cyber professionals enable their readiness to combat emerging threats and recover systems and data in the event of a cyberattack.

Both cyber professionals and athletes adhere to strict routines to maintain their proficiency and effectiveness. In cybersecurity, routines include anomaly detection, vulnerability assessments, and monitoring logs to identify any suspicious activities. Athletes, on the other hand, follow rigorous training schedules, including physical conditioning, skill development, and recovery. These routines help maintain peak performance, reduce the risk of injuries, and ensure consistent results in both fields.

Maintaining unwavering focus and concentration is vital for cyber professionals to detect and respond to threats effectively. They must constantly monitor systems, analyze data, and stay alert to any anomalies that could indicate a potential attack.

Similarly, athletes must stay focused during competitions, maintaining their composure and executing their strategies amid distractions and pressure. This ability to concentrate allows both cyber professionals and athletes to perform at their best and achieve their objectives.

The Critical Role of Teamwork and Support in Achieving Success

In the realm of cyber resiliency, teamwork is the cornerstone of an effective defense against cyber threats, including the ability to respond and recover from such threats. Just as a sports team relies on the coordinated efforts of its players to achieve victory, a successful cybersecurity strategy hinges on the seamless collaboration of experts from various disciplines. This collaborative approach enables organizations to leverage the diverse strengths and expertise of their cybersecurity professionals, supporting comprehensive protection against evolving threats.

Responding to a cyberattack will take support from your entire organization from cybersecurity and IT teams all the way to the executive team. There are many elements that need to be considered, including communications, public relations, incident response, eDiscovery and data recovery, and there are many non-technical elements that need to be executed.

 Having a holistic and comprehensive cyber resiliency plan allows you to be clear with the roles and responsibilities, including expectations and accountability. If they combine this plan with regular testing and simulation, organizations should be in the best position to respond and recover from a cyberattack. It becomes muscle memory without having to make decisions under stress – again, remarkably like how athletes prepare for big competitions.

Teamwork, support, open communication, and trust are indispensable elements for success in both cyber resiliency and professional sports. By fostering these essential qualities, organizations can build a robust defense against cyber threats and achieve their goals in the ever-evolving digital landscape.

The Impact of Technology

Technology stands as a transformative force in both cybersecurity and professional sports, revolutionizing preparation, performance, and recovery in both domains. Advanced data analytics, artificial intelligence, and machine learning have emerged as indispensable tools for cyber professionals and athletes alike.

In the realm of cybersecurity, these innovative technologies facilitate the identification of threats, enhance decision-making, and automate processes, enabling organizations to fortify their defenses against cyberattacks. Similarly, in professional sports, data analytics empower coaches and trainers to optimize training regimens, identify talent, and devise winning strategies.

Virtual and attack simulation technologies, such as Cyber Ranges and Red Teaming, further bolster preparedness and performance. In cybersecurity, simulations provide a safe environment for cyber professionals to test their response plans and hone their skills. These simulations provide a real-world attack simulation where defenders and organisations can test and stress their end-to-end cyber resiliency plans.

In sports, virtual reality technology enhances training by simulating real-world scenarios, allowing athletes to refine their techniques and strategies without the risk of injury. In swimming, we have seen the introduction of technology visually help athletes to identify improvements in their technique.

Just as professional athletes prepare and train rigorously, strategize meticulously, and adapt swiftly to the ever-changing dynamics of their sport, organizations must cultivate a robust cyber resilience strategy. This involves continuous testing, adopting advanced technologies, and fostering a culture of preparedness and agility. Both realms demand a proactive approach, unwavering commitment, and the ability to recover quickly from setbacks.

We’d love to hear your thoughts on this analogy. Do you see other parallels between cyber resilience and professional sports? How does your organization prepare for cyber threats, and what strategies have you found most effective? Share this post on LinkedIn and join the discussion.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

At Commvault, we believe that true innovation happens when you push the boundaries of what’s possible. Our recent recognition at the Zinnov Awards for Excellence in Customer Centricity highlights our commitment to excellence and the transformative culture we foster. But beyond this accolade, it’s the culture of innovation and growth that truly defines our work environment and career opportunities.

Since late 2019, our Center of Excellence (COE) in India has undergone a significant transformation. Once focused solely on engineering, the COE now represents a hub of innovation, integrating engineering expertise, global product management, and customer support to enhance experiences across India, APAC, and EMEA. This shift is more than a structural change; it’s a culture of innovation where our team is empowered to tackle complex challenges and deliver groundbreaking solutions.

For instance, our support team recently resolved a critical issue for a major client by leveraging advanced technology and insights from our Executive Briefing Center. This not only demonstrated their problem-solving capabilities but also led to new strategies that enhanced our customer engagement. Such innovative approaches are central to our culture and provide our employees with a platform to excel and grow.

At Commvault, pushing boundaries isn’t just a slogan – it’s a way of life. We provide our employees with the tools and opportunities to drive their own career growth. Through comprehensive training programs like Sales Kick-Off and Product Management Masterclass, we ensure that every team member has the chance to thrive. Our performance incentives and recognition programs such as the CEO Living Our Values Awards further encourage individuals to surpass their own expectations and contribute to our culture of continuous improvement.

Joining Commvault means becoming part of a team where innovation and growth are at the forefront. Our recent Zinnov Award is a testament to the pioneering spirit that drives us and the career advancement opportunities we offer. If you’re ready to make a significant impact and advance your career in a forward-thinking, customer-focused environment, Commvault is the place for you.

Explore our career opportunities, and see how you can contribute to our mission of setting new standards for customer excellence and innovation. Your journey to push boundaries starts here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

How do you take an hour’s worth of viewpoints from a panel of leading experts and condense it into a 5-minute read, designed to provide actionable advice you can immediately use? That’s the challenge I posed to myself as I prepared to write this blog, so let me know if I delivered. As moderator of the panel, I will share that this group laid out sound guidance based on fresh research and 60+ combined years of data industry experience. You can listen to the full panel discussion here.

The panel: Ken Malcolmson, Chief Security Advisor at Microsoft; Tony Palmer, Principal Validation Analyst at Enterprise Strategy Group (ESG); and Dalton Hirst, Senior Sales Engineer at Commvault.

Their goal: Provide proven recommendations and guidance on how to better prepare for the next cyberattack. What immediate steps can you take to avoid disruption and chaos when it takes place? Although there was a wealth of knowledge and experience shared, here are some highlights:

Cyber recovery is not the same as disaster recovery

Tony shared ESG’s research validating that “89% of those interviewed ranked ransomware as a top 5 threat to their organization, and that the ability to recover to a clean environment is essential to cyberattack recovery – and that cyber recovery is not the same as disaster recovery, so you need an entirely new plan and process. What you did for disaster recovery will not work when a cyberattack hits.”

In a nutshell, a new approach and plan is needed if you are going to be successful at protecting your business when the next attack targets your organization.

You have to be able to trust your backups – and restore to a clean environment

Ken emphasized the importance, when it comes to recovery after a cyber incident, of knowing that you have a trusted clean environment and that you have a process in place to restore your clean data to clean infrastructure. 

Ken shared that “you must have backups, you must test your backups, and you must trust your backups.” He added, “that’s where I see the value in both Commvault Cloud and Cleanroom Recovery come into play. If I’m in a panic and trying to recover, I want to be 100% sure the data I’m recovering is trustworthy, and that’s where the Commvault piece comes in, and I want to make sure that where I’m restoring to is also trustworthy, and that’s the Commvault Cleanroom Recovery solution. That’s it.” 

Simplified protection for Microsoft 365 is essential to productivity

Microsoft 365 is central to the productivity of most organizations, and enhancing its protection is crucial. Dalton discussed the simplicity of Commvault’s M365 cyber resilience solution. With it, he shared that customers “can now go in, select the data they need to restore, and restore it as needed.” This capability is crucial for responding to user requests efficiently, particularly under the stress of potential data loss scenarios.

After the live demo, Ken added, “I love the simplicity [of the Commvault] approach. When customers are panicking and trying to recover their data [in M365], they don’t want to have to click through menus and different options … there’s my recovery point, that’s the data that’s in there, go. I love that!”

Plan, test – and when you need to recover, it’s got to be clean

As the session wrapped up, Tony provided his closing advice: “In a nutshell, cyber resilience really requires a detailed and secure cyber recovery plan, and you need to do that regular, auditable testing to ensure that you can recover quickly and more importantly, into a clean environment that’s free from infection. In our testing and our research and our analysis, Enterprise Strategy Group confirmed very clearly that Commvault Cleanroom Recovery delivers what’s needed to accomplish all this. You can literally, with a click, recover into an assured clean environment.”

Watch the webinar on-demand here, and learn more about our solutions – request a demo.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Here at Commvault, our values – we connect, we inspire, we care, and we deliver – are foundational to everything we do.

This week, we hosted our quarterly internal Global Town Hall meeting and presented our FY25 Q1 CEO Living Our Values Awards. This awards program helps us to globally recognize and celebrate our Vaulters for their incredible work as they live our values each day.

I’m so proud to announce our FY25 Q1 CEO Living Our Values Award winners and our Vaulters Choice Award (employee nominated!) winner below:

Jakub Lewandowski 

Rakesh Hothur

FedRAMP High Authorization Team

Karunakar Bojjireddy

Richard Breakiron

Tirthankar Chatterjee

Jean Cleghorn

Shankaar Thiagarajan

Outage Response Team

Kyle Allocca

Ernie Costa

Tim Goulding

Tim Karaban

Prakash Kumar Ramakrishnan

Robert O’Brien

Global Field and Partner Marketing Team

Kristin Heisner

Marta Kin

Amy Ngian

Christina Reed

All these winners set an inspiring example of what it truly means to be a Vaulter!

To learn more about what it is like to work at Commvault, check out our careers site.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

While organizations may cite specific cyber security measures as priorities, it’s how they behave that truly matters. This was a key insight found in our inaugural Cyber Recovery Readiness Report, in which we partnered with GigaOm to survey 1,000 global IT and security leaders.

When analyzing the most resilient organizations, we found that they employed many measures, but five practices rose to the top when determining their true readiness. We call these practices maturity markers (see 5 Markers of Cyber Recovery Readiness, below). 

Organizations demonstrating four or five markers are considered cyber mature. These companies report experiencing fewer breaches and recovering faster when they do get breached. 

However, our survey found that only 4% of organizations have deployed all five markers, and just 13% practice at least four. At the bottom of the maturity curve, 14% have no key markers in place at all.

While fewer than half of all organizations feel confident in their recovery plans, more than half of cyber mature organizations (54%) feel substantially more confident in their ability to recover critical systems and data following a major incident. 

5 Markers of Cyber Recovery Readiness

An organization’s level of cyber maturity can be measured by the presence of five markers. The most mature, cyber-ready organizations demonstrate four or five of these:  

  • Security tools to enable early warning about risk, including insider risk. 

Early warning security tools are technologies and systems designed to detect potential cyber threats before they can cause significant harm. These tools aim to identify risks at the earliest possible stage, allowing organizations to respond proactively rather than reactively. Examples include Intrusion Detection Systems, Deception Technology, Intrusion Prevention Systems, Security Information and Event Management, User and Entity Behavior Analytics, and Endpoint Detection and Response. 

  • A known-clean dark site or secondary system in place.   

Maintaining an isolated, pre-configured or dynamic isolated recovery environment (for example, a cleanroom) that remains unaffected by cyber incidents at the primary site. This secondary site can be quickly activated for business continuity and data integrity in the event of a cyber attack or major failure. It enhances cyber resiliency by providing a secure failover option, minimizing downtime and complexities of failover.  

  • An isolated environment to store an immutable copy of the data.   

Involves maintaining a separate, air gapped (that is, immutable and indelible) copy of data secured behind a third party’s infrastructure. The data remains unchanged and protected from cyber threats, including ransomware and malicious insider actions. It enhances data integrity and availability, providing a reliable recovery option in case of data corruption or loss. 

  • Defined runbooks, roles, and processes for incident response.   

A crucial capability for cyber resilience for a structured and efficient response to cyber incidents. Tested runbooks provide step-by-step instructions for handling various types of incidents, reducing confusion and response time. Clearly defined roles and processes ensure that every team member knows their responsibilities, promoting coordinated efforts. This preparedness speeds up recovery and helps maintain operational continuity during and after cyber events. 

  • Specific measures to show cyber recovery readiness and risk.   

Metrics and tests that demonstrate an organization’s ability to recover from cyber incidents and assess associated risks. These measures, such as regular recovery drills and risk assessments, provide insight into the effectiveness of recovery plans and identify potential vulnerabilities. They are important for cyber resiliency in particular, as well as preparedness, validation of recovery strategies, and to highlight areas for improvement. 

Download the full report to find out more about how your organization can be better prepared for a breach.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

We are thrilled to announce the general availability of Commvault® Cloud Backup and Recovery for Microsoft 365 integration with Microsoft 365 Backup Storage.

Combining Commvault Cloud Backup & Recovery for Microsoft 365 and Microsoft 365 Backup Storage delivers a unified solution for high-speed in-place restores with industry-leading capabilities for compliance, granular recovery, and extended retention across your Microsoft 365 environment.

Enhancing Resilience and Recoverability Together

Joint customers can now deploy the integrated solution, Commvault Cloud with Premium Microsoft 365 Backup Storage, anytime for enhanced cyber resilience and recovery from the Commvault Cloud Console. This enables single-pane-of-glass control for Microsoft 365 protection, Commvault-provided Teams protection, and your other SaaS, hybrid, and multi-cloud workloads, all within a single platform.

The integrated solution empowers customers with choice, enabling enterprises to use Microsoft 365 Backup Storage for fast, comprehensive point-in-time recovery of their mission-critical Microsoft 365 workloads and data.

Commvault’s Microsoft 365 protection capabilities span across Teams, Exchange Online, OneDrive, and SharePoint. Commvault delivers configurable extended retention to meet regulatory requirements and flexible, granular recoverability with item-level and self-service restore options. With the combined offering, customers can select the right level of protection and recovery based on the specific Microsoft 365 workload, enhancing efficiencies and recoverability.

Getting Started

To access Commvault Cloud with Premium Microsoft 365 Backup Storage, log into the Commvault Cloud console, navigate to Commvault Cloud Backup & Recovery for Microsoft 365, and select your preferred service type during the Microsoft 365 backup configuration process.

View the walk-through demo.

Hear From the Experts

Our very own Brady Kirby, Senior Director of Product Management, is joined by Brad Gussin, Principal PM Manager for Microsoft 365 Backup, to share the benefits of our combined solutions in this podcast: Achieving Total Cyber Resilience with Commvault and Microsoft Part 1 and Part 2.

For more information on the integration, visit commvault.com/supported-technologies/microsoft/microsoft-365-backup-storage.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Starting in August 2024, Commvault® Cloud Cleanroom™ Recovery will support SaaS, Active Directory, and Repave using “Golden Image.” This release will further emphasize Commvault’s commitment to cyber readiness and resilience for our customers.

Cybersecurity breaches are inevitable; customers need to embrace and plan accordingly. Now, SaaS customers can be recovery-ready by conducting cyber recovery testing. Testing has historically been complex and increasingly expensive. This release will enable our SaaS customers to do the same without the complexities and unpredictable expenses.

Cleanroom Recovery for SaaS: How does it work?

Cleanroom Recovery for SaaS provides seamless integration with the SaaS control plane:  

  • For centralized management.
  • Automated scaling of Access nodes and Media Agents to meet the dynamic needs of SaaS workloads.
  • Support for multi-tenancy to accommodate diverse environments.
  • Comprehensive API access for enhanced automation and tool integration.
  • Delivering feature parity between software and SaaS solutions for uniform functionality across deployment models.

Users can log into their SaaS portal, create recovery groups, and perform cleanroom recovery orchestration into their Azure subscription. The experience remains the same, so SaaS customers can perform regular testing to better understand vulnerabilities, incident response and forensics, and high-speed recovery. Cleanroom Recovery in SaaS is a secure and quick recovery of applications into an on-demand cleanroom to enable reliable cyber recovery.

The SaaS Control Plane is within Commvault’s infrastructure. If a SaaS customer wants to do a cyber recovery testing or investigation, or a recovery, they would need to identify where the Cleanroom needs to aux copy the backup data into Commvault AirGap.

Once this is available, they create an Azure subscription and bring their own infrastructure (the networking components), and then orchestrate the recovery of the application using Commvault AirGap into the defined Cleanroom. This process can be automated, and any recovery validation can be performed with this being orchestrated.

The difference between software and SaaS is straightforward. In software, the control plane is running inside production, and the first step is to recover it and perform application recovery. In the case of SaaS, the control plane is already within our infrastructure. It is isolated from the customer environment, and we are targeting application recovery.

Active Directory Recovery + Cleanroom Domain Controller Recovery

The August release of Cleanroom Recovery also will include Active Directory. Active Directory is an important component of any application, and when it comes to cyberattacks, attackers don’t just infect a singular component, VMs, or databases. They want to insert themselves into the Active Directory as an admin user, make changes, and modify. So, it’s mission-critical to make sure that AD is recovered from a clean point. With multiple elements involved in recovering applications, organizations need a single management point that can perform mass recovery.

Cleanroom Recovery support for Active Directory streamlines the entire recovery and recovery validation process. Customers don’t need to deploy a new Active Directory or manually recover an Active Directory before performing a cleanroom recovery.

Benefits:

  • Accelerate investigations to identify and recover lost directory data as quickly as possible, which is crucial for maintaining operational continuity and security within the organization’s IT infrastructure.
  • Rollback overwritten or corrupted attributes in mass across hundreds of objects at once.
  • Streamlines the recovery process of the entire application, including AD.

Pave / Repave – “Golden Image”

Cleanroom Recovery of VMs using Golden Image enables customers to use templates to create the Azure VM in the cleanroom before restoring the data to the VM.

Benefits:

  • Flexibility to use the public marketplace and private custom templates for Azure VM creation enhances recovery precision and adaptability.
  • It provides a streamlined recovery process by creating a new Azure VM from a template before restoring data. This allows for a clean and efficient restoration with the complexities of OS drive content.
  • Start with a known, trusted configuration, which minimizes the likelihood of reintroducing malicious code into the clean environment.

Prerequisites:

Commvault:

  • Application backup aux copied to Commvault AirGap

Customer Environment:

  • Active Directory or other identity management, free of infection, is already up and running in the cleanroom.
  • A clean Azure tenant (customer subscription) with
    • Network resources created and configured.
  • Resource groups and storage accounts created and configured.
  • Key management service encryption key configured.
  • IAM Access is configured to access the resources.

Key Requirements for SaaS:

  • CRR subscription is required.
    • 10 TB increments
    • Usage is metered based on the amount of data configured in “Recovery Groups.”

Support Matrix:

Workloads

  • VM’s VMware (On-prem, AWS VMC, Azure AVS, Google Cloud VMware, OCI VMware, Azure, AWS, Hyper-V)
  • Active Directory (installed on any of the VMs)
  • Databases (SQL server, Oracle, and DB2 installed on VMs)

Cleanroom Target

  • MSFT Azure

Storage

  • Commvault AirGap

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

Here at Commvault, we have celebrated Disability Pride Month across our global Vaulter community with open dialogues and educational initiatives hosted by our CapAbilities Employee Resource Group (ERG) and Diversity, Equity, and Inclusion (DEI) team.

It is our CapAbilities ERG’s mission to raise awareness and break down the bias of workplace issues that affect people with disabilities and/or caregivers of those with a disability. It is equally important to be an ally to our disability community to create an environment where all our Vaulters feel valued and respected.

To conclude our celebration of Disability Pride Month, we hosted a virtual Courageous Conversation where we were joined by Coach Jordene, a children’s gymnastic coach who champions inclusion and leads with empathy.

During the conversation, Coach Jordene shared how growing up with a brother with Down Syndrome made her passionate about disability pride and working in the special needs community. Jordene has been involved in the special needs community since she was a young girl and always jumped at the chance to show what inclusion looks like. She was fortunate enough to combine her love of gymnastics and working with the special needs community when she started her Xcel team at her local gym.

Her gymnastics program at Action Gymnastics differs from more traditional gyms and classes. The gym offers both youth and adults classes to foster inclusion of all ages. She also shared her insights on how the community at her gym interacts with the differently abled teams that she coaches – it has a positive impact for everyone and teaches teams of all ages the importance of empathy.

Before the conversation ended, Coach Jordene answered questions from Vaulters on the challenges that she faces when running this program. It was so inspiring to hear from Jordene about her team and role as a coach.

This Courageous Conversation was another opportunity for us to talk about the importance of inclusivity and following your passion. Click here to learn more about our DEI efforts at Commvault.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery

For security and IT professionals, the risk landscape is constantly evolving, and they are particularly concerned about external threats and breaches. Organizations realize it’s not a matter of if or when they will be breached, but a matter of what to do when they find out they have already been breached. 

We partnered with GigaOm to survey 1,000 IT and security leaders globally for our inaugural Cyber Recovery Readiness Report – and we learned a lot about the daunting set of challenges they face.

Respondents’ top security challenges include increasingly sophisticated hackers and attack types, use of artificial intelligence by cybercriminals, a broader attack surface due to cloud and SaaS, and adopting AI-based technologies across security tooling.  

Our respondents’ adoption of several general security capabilities – identity and access management; intrusion protection, detection, and response; data loss prevention/protection; and security posture management – hovers in the 75% to 80% range, with the current solution in place either satisfactory or in need of improvement. However, looked at generally, 42% of respondents are satisfied with their general cybersecurity, while 38% see a need for improvement to their cybersecurity measures.  

When it comes to cyber recovery, the top challenge named in our survey was the complexity of critical apps and data, cited by 44% of respondents, followed by cost. A significant number of organizations (42%) lack a clear understanding of who is responsible for driving cyber resilience and recovery strategies and execution.

Fortunately for those organizations that lack clear ownership for cyber recovery strategies – and for the 38% whose cybersecurity measures need improvement – the full Cyber Recovery Readiness Report is available now. It’s full of actionable insights that will leave you better prepared to withstand and recover from a breach, including the five maturity markers we found in cyber resilient organizations. Download it here.

More related posts


Thumbnail_Blog-Clumio-Chat-2026

Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection

Read more about Meet Clumio Chat: An AI Assistant to Help Evaluate Cloud-Native Data Protection
Thumbnail_Blog-Clumio-Fedramp-2026

Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone

Read more about Clumio Advances Cloud-Native Cyber Resilience with FedRAMP® Milestone
Thumbnail_Blog_Agentic-Ransomware-Attack

Cyber Resiliency for AI and Ransomware Recovery

Read more about Cyber Resiliency for AI and Ransomware Recovery